Robin H. Johnson wrote:
This patch adds a new configuration option 'tls_before_auth', that when set, does not offer AUTH until the connection has been secured. This helps to prevent password disclosures with SASL LOGIN/PLAIN mechanisms.
Applied, thanks! You provided a patch to README (good, I don't remember to do that piece) but we also include a sample configuration in config.sample, which I created before applying.
I also committed your "SSL in header" patch at the same time. Thanks John
